PT-2019-2793 · Cisco · Cisco Small Business 300 Series Switches+2

Publicado

2019-07-17

·

Atualizado

2019-10-09

·

CVE-2019-1943

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Small Business 200, 300, and 500 Series Switches software (affected versions not specified)
Description A vulnerability in the web interface could allow an unauthenticated, remote attacker to redirect a user to a malicious web page due to improper input validation of HTTP request parameters. This is known as an open redirect attack, often used in phishing attacks to trick users into visiting malicious sites. An attacker could exploit this by intercepting and modifying a user's HTTP request to cause the web interface to redirect the user to a specific malicious URL.
Recommendations For Cisco Small Business 200, 300, and 500 Series Switches software, consider restricting access to the web interface until a fix is available. As a temporary workaround, avoid using the web interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02745
CVE-2019-1943

Produtos afetados

Cisco Small Business 200 Series Switches
Cisco Small Business 300 Series Switches
Cisco Small Business 500 Series Switches